CVE-2019-12470

MEDIUM6.5EPSS 0.17%

Wikimedia MediaWik exposed suppressed log in RevisionDelete page

Published: 5/24/2022Modified: 4/28/2026
Also known as:GHSA-733q-m38x-q7ccDEBIAN-CVE-2019-12470

Description

Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (8)